mm2-analytics-roblox-tracker

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to clone a repository from https://8015238355.github.io. Cloning from a GitHub Pages subdomain rather than a standard repository is highly irregular and represents an unverifiable source for executable code, which is then run via setup.sh.
  • [PRIVILEGE_ESCALATION]: The troubleshooting section encourages the use of sudo ./setup.sh --install. This directs the user to grant administrative privileges to a shell script downloaded from an untrusted and suspicious remote source.
  • [METADATA_POISONING]: While the skill's frontmatter and README claim it is for "analytics and inventory management," the installation instructions reveal the project directory is named murder-mystery-dupe-roblox. The term "dupe" is a well-known red flag in the Roblox community, typically associated with item duplication scams and malicious account-stealing scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted gameplay data, creating a potential injection surface.
  • Ingestion points: Reads gameplay data from ./data/gameplay_history.json and ./data/raw_gameplay.json (SKILL.md).
  • Boundary markers: None identified in the instruction set to separate untrusted data from system prompts.
  • Capability inventory: Capability to execute shell commands (setup.sh) and perform network operations via AIIntegration using external API keys.
  • Sanitization: No evidence of input validation or escaping for the ingested JSON data.
  • [COMMAND_EXECUTION]: The skill uses chmod +x setup.sh and ./setup.sh to execute arbitrary shell commands during the installation process.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — mm2-analytics-roblox-tracker